๐Ÿ” CVE Alert

CVE-2020-36960

MEDIUM 6.4

Forma LMS 2.3 - 'First & Last Name' Stored Cross-Site Scripting

CVSS Score
6.4
EPSS Score
0.0%
EPSS Percentile
0th

Forma LMS 2.3 contains a stored cross-site scripting vulnerability that allows attackers to inject malicious scripts into user profile first and last name fields. Attackers can craft scripts like '<script>alert(document.cookie)</script>' to execute arbitrary JavaScript when the profile is viewed by other users.

CWE CWE-79
Vendor formalms
Product forma lms
Published Jan 26, 2026
Last Updated Mar 5, 2026
Stay Ahead of the Next One

Get instant alerts for formalms forma lms

Be the first to know when new medium vulnerabilities affecting formalms forma lms are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Changed
Confidentiality
Low
Integrity
Low
Availability
None

Affected Versions

Formalms / Forma LMS
0 โ‰ค 2.3

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
exploit-db.com: https://www.exploit-db.com/exploits/49197 formalms.org: https://www.formalms.org/ vulncheck.com: https://www.vulncheck.com/advisories/forma-lms-first-last-name-stored-cross-site-scripting

Credits

Hemant Patidar (HemantSolo)